Known Vulnerabilities for Taocms by Taogogo
Listed below are 9 of the newest known vulnerabilities associated with "Taocms" by "Taogogo".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-23880 | An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute ar... | 9.8 - CRITICAL | 2022-03-23 | 2022-03-28 |
| CVE-2022-23380 | There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit. | 8.8 - HIGH | 2022-03-01 | 2022-03-08 |
| CVE-2022-23316 | An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admin.php... | 4.9 - MEDIUM | 2022-02-04 | 2022-02-08 |
| CVE-2021-34167 | Cross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via taoc... | 8.8 - HIGH | 2023-02-24 | 2023-03-03 |
| CVE-2021-25785 | Taocms v2.5Beta5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Management column. | 4.8 - MEDIUM | 2021-12-02 | 2021-12-03 |
| CVE-2021-25784 | Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Edit Article. | 7.2 - HIGH | 2021-12-02 | 2021-12-04 |
| CVE-2021-25783 | Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Article Search. | 7.2 - HIGH | 2021-12-02 | 2021-12-04 |
| CVE-2020-20725 | Cross Site Scripting vulnerability in taogogo taoCMS v.2.5 beta5.1 allows remote attacker to execute arbitrary code via the n... | 6.1 - MEDIUM | 2023-06-20 | 2023-06-30 |
| CVE-2019-7720 | taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making a co... | 9.8 - CRITICAL | 2019-02-11 | 2019-02-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Taogogo | Taocms | 2014-05-24 | All | All | All |